logo

11 Malicious NuGet Game Cheat Packages Deploy Pepesoft Windows Surveillance Malware

ID: cb35334f-5631-5e83-b43b-e88f010e030f

STIX ID: report--cb35334f-5631-5e83-b43b-e88f010e030f

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-07-15

Date Updated: 2026-07-21

Author: Mayura Kathir

...
...

Socket’s Threat Research Team identified 11 malicious NuGet DotnetTool packages masquerading as game cheats and management panels that stage and execute a Windows payload (pepesoft.exe) and PyInstaller-based variants; the malware uses Google DNS-over-HTTPS for evasion, retrieves payloads from GitHub Releases and Hugging Face, leverages Cloudflare Workers/Selectel for configuration, and exfiltrates system data and screenshots (including OCR and Telegram bot functionality). Organizations should audit NuGet tool installations, investigate pepesoft.exe execution, monitor developer-tool DoH queries to dns.google, and block or sinkhole the listed infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.